Detection and monitoring EU-developed
Gatewatcher NDR
Network detection and response platform that analyses traffic and metadata, prioritizes suspicious activity, and supports threat hunting and incident investigation.
By Gatewatcher · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- Gatewatcher
- Recorded country
- France
- Product model
- Commercial
- Deployment
- Self-hosted / SaaS
- Software license
- Commercial license; full terms not publicly verified
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteDeveloped by French company Gatewatcher, which identifies its own NDR platform and has headquarters in France.
Reported capabilities
- Analyzes network communications and metadata for behavioral threats.
- Aggregates and prioritizes alerts for SOC investigation.
- Vendor describes on-premises, SaaS and hybrid deployment options.
Scope and limits
Gatewatcher NDR is one platform; Decision Center, AIonIQ, sensors, and TAPs are not split as standalone CSIRT software here. Full product license terms were not publicly verified.
Inspect the research evidence 5 source observations
identity / capabilities
Current product page describes AIonIQ network analysis, metadata visibility, alert aggregation, triage and threat hunting.
Read sourceorigin / country / maintenance
Official 2026 company statement calls Gatewatcher French, says it developed its NDR platform, and describes ongoing platform development.
Read sourcecountry
The official locations page lists Gatewatcher headquarters at La Défense, France.
Read sourcedeployment
Vendor case page explicitly describes on-premises, SaaS and hybrid deployment of the commercial NDR solution.
Read sourcelicense
The official NDR offer presents commercial deployment but does not publish full customer software rights or product license terms in the reviewed page.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection